PT-2019-1773 · Cisco · Cisco Small Business Spa514G Ip Phone
Published
2019-03-13
·
Updated
2019-10-09
·
CVE-2018-0389
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Small Business SPA514G IP Phones versions 7.6.2SR2 and earlier
Description
A vulnerability in the implementation of Session Initiation Protocol (SIP) processing could allow an unauthenticated, remote attacker to cause an affected device to become unresponsive, resulting in a denial of service (DoS) condition. The vulnerability is due to improper processing of SIP request messages by an affected device. An attacker could exploit this vulnerability by sending crafted SIP messages to an affected device. A successful exploit could allow the attacker to cause the affected device to become unresponsive, resulting in a DoS condition that persists until the device is restarted manually.
Recommendations
For Cisco Small Business SPA514G IP Phones versions 7.6.2SR2 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the SIP protocol to minimize the risk of exploitation. Avoid using the affected SIP implementation until the issue is resolved.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Small Business Spa514G Ip Phone